CVE-2026-90456
9.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials will expose that component's administrative interface to anyone aware of the default value.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| CISA | Malcolm | 0 < v26.06.0 | affected |
| CISA | Malcolm | v26.06.0 | unaffected |
Weaknesses
- CWE-1392: CWE-1392 Use of default credentials
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.